NA - CVE-2024-42902 - An issue in the js_localize.php function of...
An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php...
NA - CVE-2024-42903 - A Host header injection vulnerability in the...
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to...
NA - CVE-2024-42904 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at...
NA - CVE-2024-7619 - Rejected reason: Rejected reason: DO NOT USE...
Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable...
NA - CVE-2024-43413 - Xibo is an open source digital signage platform...
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to...
NA - CVE-2024-43803 - The Bare Metal Operator (BMO) implements a...
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and `networkData` for the...
NA - CVE-2024-45307 - SudoBot, a Discord moderation bot, is...
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration...